USN-4135-1
Dashboard / Vulnerabilities / USN-4135-1
USN-4135-1
Summary: linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-gke-5.0, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
Details: Peter Pi discovered a buffer overflow in the virtio network backend (vhost_net) implementation in the Linux kernel. An attacker in a guest may be able to use this to cause a denial of service (host OS crash) or possibly execute arbitrary code in the host OS. (CVE-2019-14835) It was discovered that the Linux kernel on PowerPC architectures did not properly handle Facility Unavailable exceptions in some situations. A local attacker could use this to expose sensitive information. (CVE-2019-15030) It was discovered that the Linux kernel on PowerPC architectures did not properly handle exceptions on interrupts in some situations. A local attacker could use this to expose sensitive information. (CVE-2019-15031)
References: https://ubuntu.com/security/notices/USN-4135-1, https://ubuntu.com/security/CVE-2019-14835, https://ubuntu.com/security/CVE-2019-15030, https://ubuntu.com/security/CVE-2019-15031
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
